Over 900 customers trust the best software for
information security, business continuity, and data privacy.
Build trust, ensure compliance, minimize risks.
The introduction of an internal reporting channel has become mandatory for many companies under the Whistleblower Protection Act (HinSchG) and the EU Whistleblower Directive. However, beyond mere compliance, an effective whistleblower system offers the opportunity to identify risks early on and protect your company’s integrity.
With the whistleblowing module of the AKARION GRC Cloud, you’re not just implementing a legally compliant reporting channel. You’re establishing a solution that guarantees absolute anonymity and seamlessly integrates reports into your existing security and handling processes. Protect whistleblowers and your company alike.
Guaranteed Anonymity & Security
Security is our top priority. Our module ensures the confidentiality and anonymity of whistleblowers as required by law.
-
Encrypted Communication: Secure exchange between whistleblowers and case handlers.
-
Granular rights management: Ensure that only authorized individuals have access to sensitive case files.
Seamless Workflow & Deadline Management
Never miss a legal deadline again. The system guides you through the entire processing workflow in a structured manner.
-
Deadline Monitoring: Automatic reminders for acknowledgments of receipt and responses in accordance with the HinSchG.
-
Centralized case management: Process, document, and close cases in one central location.
Customizable & Multilingual
No two companies are alike. Tailor the whistleblower system to your organizational structure.
-
Custom reporting forms: Create specific forms for different whistleblower groups (employees, suppliers, partners).
-
Multilingual Support: Offer reporting channels in multiple languages—including automatic translation via the AKARION GRC Cloud.
-
CI/CD Compliant: Customize the look and feel of the reporting portal to match your corporate design.
Custom Design
Customize the look and feel of the reporting portal to match your corporate design.
The Benefits of the AKARION Whistleblowing Module
Completely Anonymous
Seamlessly Integrated
No more data silos: In the AKARION GRC Cloud, reports are automatically converted into incidents for ISMS or data privacy. Leverage synergies and manage all risks and measures on a single central platform.
Smart & Efficient
Save time from day one: Replace manual processes with automated workflows and use our Smart Content AI and extensive template libraries to process cases quickly.
Secure Across the Entire Group
Whether you’re dealing with a complex holding structure or supply chain, you can easily comply with the HinSchG and LkSG across all organizational boundaries. Manage as many clients as you need centrally, while ensuring they are clearly separated in accordance with data protection regulations.
98% of our customers renew their licenses.
Marco van Schoonderwaldt
Information Security Management Expert
The choice fell on the AKARION GRC Cloud—a decision that not only meets current needs but also supports future growth, particularly with regard to accessibility.
Frank Peter
Head of Data Privacy and Data Security
With the AKARION GRC Cloud, our consultants can effectively integrate data privacy and information security, thereby optimally meeting our clients’ needs. At the same time, we have become significantly more efficient. It’s a win-win situation for everyone involved.
Christian Bockrath
Information Security Officer
I have finally found software that allows me to conduct comprehensive risk analyses while taking both information security and data privacy into account. The resulting synergies can be fully leveraged.
Beatrice Dietrichsteiner
CISO and Project Success Manager
The AKARION GRC Cloud helps us map business processes quickly and easily and determine security requirements. Combined with smart features that also strengthen business continuity, it allows us to identify instances of non-compliance with SLAs and OLAs. The workflows, in particular, have become indispensable to us.
Theresa Steinmetz
Information Security Risk Manager
Data is our most valuable asset. It must be protected. Compared to the old Excel solution, the GRC Cloud saves us an enormous amount of time. I would estimate this at around 60 percent. In terms of usability, the improvement is actually 100 percent.
Andreas Bögemann
Managing Director
The automatic audit schedules allow for systematic and regular audits. All key information is automatically displayed in a clear and concise manner on the ISMS module’s dashboard. This significantly reduces the effort required compared to a manual audit!
Daniel Holzer
Managing Director
As the leading IT provider for municipalities in Upper Austria, we need a solution that is practical and intuitive to map the complex structures of public administration. The AKARION GRC Cloud helps us keep our municipalities’ documentation up to date and conduct annual audits efficiently.
Alexander Dressler
Data Protection Manager
Data is our most valuable asset. It must be protected. Compared to the old Excel solution, the GRC Cloud saves us an enormous amount of time. I would estimate this at around 60 percent. In terms of usability, it’s actually 100 percent.
Tobias Schmidt
Security & Compliance
The comprehensive solution that AKARION offers through its GRC Cloud—covering data privacy, information security, risk management, and auditing—was exactly what we needed. The GRC Cloud serves as the central hub connecting our decentralized systems. This helps us immensely in locating the information we need.
Excellence is no coincidence.
That is why we regularly subject ourselves to the most rigorous tests and are actively involved in shaping the standards of tomorrow. The certifications and memberships listed here are a matter of course for us—and for you, they are a guarantee that you are working with a partner on equal footing.
Partner of the BSI Alliance for cybersecurity
Member of Bitkom e. V.
The entire development process is ISO 27001 certified
Licensed provider of BSI
Grundschutz tools
FAQ: Whistleblowing Module
-
Under the Whistleblower Protection Act (HinSchG), who is required to establish a reporting channel?
In Germany, companies with 50 or more employees are legally required to establish an internal reporting office. This also applies to government agencies, local authorities, and companies in the financial services sector, regardless of the number of employees. With the AKARION Whistleblowing Module, you can immediately comply with these legal requirements and the EU Whistleblower Directive in a legally compliant manner, thereby avoiding fines.
-
How does the software ensure the anonymity of whistleblowers?
Anonymity is the most important factor in the system’s acceptance. Our solution uses state-of-the-art encryption technologies to protect the reporter’s identity. Even administrators do not have access to the data unless explicitly authorized to do so. An encrypted, anonymous backchannel nevertheless enables communication (e.g., for follow-up questions) between case handlers and whistleblowers without the need to disclose personal information.
-
Can I also use the system for the Supply Chain Due Diligence Act (LkSG)?
Yes, absolutely. The AKARION module is ideal for use as a complaint procedure under the LkSG. You can easily open the digital reporting channel to external stakeholders such as suppliers or business partners. Thanks to its multi-tenant capability, reports from the supply chain can be clearly separated from internal employee reports while still being managed centrally.
-
What are the benefits of integrating with the AKARION GRC Cloud compared to standalone solutions?
The biggest advantage is the elimination of data silos. A report submitted through the whistleblowing channel often highlights risks related to data privacy or information security. In the AKARION GRC Cloud, you can directly generate an incident for your ISMS or DSMS from a report and derive appropriate actions. This transforms a legal obligation into a strategic risk management tool.
-
Where is the data hosted, and is the system GDPR-compliant?
Data sovereignty is our top priority. The AKARION GRC Cloud is hosted exclusively in ISO 27001-certified, high-security data centers within the EU (Germany/France, Open Telekom Cloud). We guarantee full GDPR compliance and offer maximum protection against unauthorized access through our detailed role and rights management ("need-to-know" principle).
-
How quickly can the whistleblower system be up and running?
Since this is a SaaS (Software as a Service) solution, no local installation is required. Thanks to our extensive library of templates for reporting forms and processes, you can theoretically go live within a few hours. All you need to do is share the link to the reporting portal with your employees.
One platform, all solutions
Expand the information security module with modules for BCM, data privacy, and auditing. The path to an integrated management system has never been easier.